FOUNDED 2025 · INDEPENDENT UK PRACTICE
01Independent practice

Information security and AI governance, made practical.

InfoSecAI is an independent UK consultancy. We work with boards, audit committees and senior security leaders to translate regulatory pressure, risk appetite and operational reality into governance, controls and evidence that hold up under scrutiny.

Choose by pressure point

Regulatory pressure, AI adoption and assurance demand are converging. Start where it sits.

Three routes into the practice, by the situation in front of you. Each routes to the right advisory shape, the right deliverables and the right senior practitioner involvement.

Where to next
FOUR WAYS TO CONTINUE
03Toolkits · private preview

Practitioner-built toolkits that turn standards, regulation and assurance work into structured evidence.

Practitioner-built. AI-assisted for the structured tasks. Senior-reviewed for the judgement. Currently available through advisory-led private preview, with direct senior practitioner support. General availability anticipated H2 2026.

04Frameworks & standards

Mapped to the standards your auditors, customers and regulators already recognise.

Seven international standards underpin most senior security and AI governance programmes. Each is mapped to the management system, the controls, and the evidence auditors expect to see.

  • [01]ISO/IEC 27001:202293 CONTROLS
  • [02]ISO/IEC 42001:2023AI MGMT SYS
  • [03]NIST CSF 2.06 FUNCTIONS
  • [04]NIST AI RMF 1.04 FUNCTIONS
  • [05]CIS Controls v8.118 CONTROLS
  • [06]SOC 2 (TSC 2017, rev. 2022)5 CRITERIA
  • [07]Cyber Essentials & CE PlusUK NCSC
05Regulations

Translate statutory obligations into control activity, governance decisions and evidence.

Seven UK and EU regulations at the centre of current senior practice. For each, a current reading of the statutory text, the supervisory guidance, and the control activity boards are now expected to evidence.

  • [01]UK GDPR & DPA 2018IN FORCE
  • [02]DUAA 2025ROYAL ASSENT
  • [03]EU AI ActANNEX III · 2 AUG 2027
  • [04]DORAIN FORCE JAN 2025
  • [05]NIS 2NATIONAL TRANSPOSITION
  • [06]PCI DSS 4.0.1IN FORCE
  • [07]DSPT (NHS)ANNUAL
06Sector practice

Adapted to the regulator, the customer base, and the operating model.

Security and AI governance expectations differ by sector. Each row shows the dominant regulatory anchor and the typical control set we work to.

01

Financial Services

FCA and PRA regulated firms, banks, building societies, fintechs, payment institutions and investment firms. Subject to ICT and operational resilience oversight under DORA, FCA SS1/21 and the PRA SMCR.

TYPICAL CONTROL SET · ISO 27001 · NIST CSF 2.0 · DORA pillars · PCI DSS 4.0.1
Regulatory anchor
DORA · in force Jan 2025
02

Healthcare

NHS trusts, ICBs, primary care networks, health-tech, life sciences, clinical research and adult social care. Subject to DSPT, National Data Guardian standards and MHRA cybersecurity expectations for connected devices.

TYPICAL CONTROL SET · DSPT 2024-25 · ISO 27001 · NCSC CAF · clinical data flows
Regulatory anchor
DSPT · annual
03

Government & Public

Central government, local authorities, arm's length bodies, defence contractors and CNI operators. Subject to GovAssure, the NCSC Cyber Assessment Framework and the SCIDA arrangement.

TYPICAL CONTROL SET · NCSC CAF · GovAssure · SCIDA · ISO 27001 · supply chain
Regulatory anchor
GovAssure · annual
04

Technology

SaaS providers, cloud platforms, AI and data businesses, marketplaces and developer tooling vendors. Subject to customer-driven SOC 2, ISO 27001 procurement gating, and EU AI Act provider/deployer obligations.

TYPICAL CONTROL SET · SOC 2 · ISO 27001 · ISO 42001 · EU AI Act · NIST AI RMF
Regulatory anchor
EU AI Act · Annex III 2 Aug 2027
05

Telecommunications

Public electronic communications providers, ISPs, MNOs, MVNOs and managed network providers. Subject to the Telecommunications (Security) Act 2021 and the TSA Code of Practice with OFCOM oversight.

TYPICAL CONTROL SET · TSA 2021 · OFCOM compliance · NCSC CAF · supply chain assurance
Regulatory anchor
TSA Tier 1/2 · annual
06

Manufacturing

Industrial manufacturers, OT environments, automotive, aerospace and connected-product engineering. Subject to NIS 2 essential and important entity duties through EU subsidiaries and IEC 62443 customer expectations.

TYPICAL CONTROL SET · NIS 2 · IEC 62443 · ISO 27001 · OT segmentation · supply chain
Regulatory anchor
NIS 2 · national transposition · sector scope
07

Retail & e-commerce

Multichannel retailers, e-commerce platforms, marketplaces and consumer brands handling cardholder data. Subject to PCI DSS 4.0.1 and UK GDPR, with B2B customer security questionnaire activity.

TYPICAL CONTROL SET · PCI DSS 4.0.1 · ISO 27001 · UK GDPR · third-party risk
Regulatory anchor
PCI DSS 4.0.1
08

Professional Services

Law firms, accountancy practices, management consultancies and senior advisory firms with significant client-data sensitivity. Subject to client security questionnaires, SRA Code and ISO 27001 customer expectations.

TYPICAL CONTROL SET · ISO 27001 · SOC 2 · UK GDPR · SRA Code of Conduct
Regulatory anchor
Client & SRA audits
08Blog · dispatches

Short-form briefings on the regulatory and governance shifts security leaders need to act on.

The working journal. Weekly dispatches on current regulatory positions, supervisory expectations and the questions clients are putting on the table. Distributed via The Brief.

JUST PUBLISHED 13 MAY 2026 · FRAMEWORKS · 8 MIN READ

The Multi-Framework Crosswalk Every UK Security Leader Should Have on Their Wall

Most organisations are now reporting against three or four frameworks at once. The same controls show up in ISO 27001, NIST CSF, CIS Controls, DORA and NIS 2, but the language differs and the evidence requirements diverge in places that matter at audit time.

Read the dispatch
09Founder & principal practitioner
Paul Jolliffe, Founder of InfoSecAI
Credentials
  • MBA
  • CISSP
  • ISO 27001:2022 LA
  • ISO 27001:2022 LI
  • ISO 27001:2022 IA
  • PRINCE2 Practitioner
Independent senior practice

Paul Jolliffe. Senior information security and AI governance practitioner.

Twenty years of international senior security leadership across the private and public sectors. Roles span Chief Information Security Officer, Head of Cyber Security, Head of Managed Security Services, and senior consulting and programme management.

Deep practice across the public and private sectors, including financial services, manufacturing, healthcare, energy, telecommunications, technology and professional services. Strategy aligned to ISO 27001, NIST, CIS Controls, DSPT and CAF, with compliance work spanning PCI DSS, GDPR and UK GDPR, NIS 2, and SOC 1 and 2.

InfoSecAI was founded in 2025 for organisations that require clarity, senior leadership and hands-on delivery, without adding complexity or treating compliance as a paperwork exercise.

Recent senior roles
2021 — PRESENT
  • 2025 — NOW
    Founder & Principal Practitioner
    InfoSecAI
  • 2025
    Chief Technical Security Officer (vCISO)
    Phoenix Software
  • 2024 — 25
    Senior Cyber Security Programme Manager
    Philip Morris International
  • 2022 — 24
    Chief Information Security Officer
    Britannia Financial Group
  • 2021 — 22
    Head of Cybersecurity
    MTN

Earlier career  ·  Senior consulting, security product and programme leadership across IBM, KPMG, PwC and Deutsche Telekom (T-Systems).

The Brief · weekly

A weekly working journal for security and AI governance leaders.

Short dispatches on what is changing in UK and EU regulation, what supervisory teams are now asking, and the artefacts that hold up under scrutiny. No tracking pixels, no marketing automation, no upsell sequences. Unsubscribe in one click.

Delivered Wednesdays. Processed by Beehiiv (see privacy). Read-only address used for delivery and unsubscribe.

10First conversation

Tell us what needs to change. We will help shape the next move.

In thirty minutes we will clarify the decision, the regulatory or assurance pressure, the likely evidence gap, and the next practical move, whether or not InfoSecAI is the right delivery partner.

No pitch deck. A working conversation with a senior practitioner.